restate-workflows

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior mostly matches its stated purpose as a workflow bridge and it avoids direct Redis/internal-package access, but it relies on a project-specific `joelclaw` binary whose public installation and release provenance is not clearly verifiable from the evidence. The skill also enables real queue/workflow submissions and recommends loading another skill first, raising trust-chain and operational-risk concerns without clear signs of credential theft or overtly malicious behavior.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 12:40 PM
Package URL
pkg:socket/skills-sh/joelhooks%2Fjoelclaw%2Frestate-workflows%2F@e7ea3a168610cbec121be79c2247e4f898bfb748